![]() |
|
Plagegeister aller Art und deren Bekämpfung: immer wieder neue Setup.exe in Temp-OrdnerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() immer wieder neue Setup.exe in Temp-Ordner Hallo zusammen, Ich habe seit ein paar Tagen immer wieder eine merkwürdige Setup.exe in meinem Temp-Ordner. Aus dem Nichts heraus kommt dann jedesmal die Abfrage, ob ich die Installation zulassen will oder nicht. Natürlich klick ich dann immer auf Nein. CCleaner und Spybot hab ich schon etliche Male gestartet. Bringt aber nichts. Das letzte mal hat sich die Setup.exe auf meinem Laptop gemeldet, unmittelbar, nachdem ich CCleaner und Spybot laufen lassen hab. Wie in der Anleitung beschrieben, hab ich alle Scans ausgeführt und poste sie hier wie folgt: defogger_disable.log : defogger_disable by jpshortstuff (23.02.10.1) Log created at 22:34 on 22/12/2013 (max) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- --------------------------------- Addition.txt :FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-12-2013 01 Ran by max at 2013-12-22 22:37:23 Running from C:\Users\max\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) Adobe AIR (x32 Version: 3.8.0.1430) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Amazon Kindle (HKCU) Apple Application Support (x32 Version: 2.3.4) Apple Software Update (x32 Version: 2.1.3.127) Ashampoo Burning Studio Elements 10.0.9 (x32 Version: 3.1.1) Ask Toolbar (x32 Version: 12.9.1.17) <==== ATTENTION avast! Free Antivirus (x32 Version: 9.0.2008) Brother MFL-Pro Suite DCP-195C (x32 Version: 1.0.1.0) calibre (x32 Version: 0.8.28) Canon Utilities CameraWindow DC 8 (x32 Version: 8.9.0.4) Canon Utilities Digital Photo Professional (x32 Version: 3.12.20.0) Canon Utilities ImageBrowser EX (x32 Version: 1.2.1.13) Canon Utilities PhotoStitch (x32 Version: 3.1.23.47) CCleaner (Version: 4.08) CDex - Open Source Digital Audio CD Extractor (x32 Version: 1.70.4.2009) Celestia 1.6.0 (x32) Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000) Exif-Viewer 2.50 (x32 Version: 2.50) Explorer Suite III FileParade Bundle (x32 Version: 1.0.0.0) GIMP 2.8.4 (Version: 2.8.4) Google Chrome (x32 Version: 31.0.1650.63) Google Earth (x32 Version: 7.1.1.1888) Google Update Helper (x32 Version: 1.3.22.3) Image Resizer Powertoy Clone for Windows (64 bit) (Version: 2.1.1) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) K-Lite Codec Pack 7.6.0 (Full) (x32 Version: 7.6.0) MainConcept MJPEG Codec Demo (x32 Version: 3.02.0004.0000) MainConcept MJPG software codec (Remove Only) (x32) McAfee Security Scan Plus (Version: 3.8.130.10) MediaInfo 0.7.61 (Version: 0.7.61) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0) Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Works (x32 Version: 9.7.0621) Motorola Driver Installation 3.9.0 (Version: 3.9.0) Movie Studio Platinum 12.0 (64-bit) (Version: 12.0.756) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0) Mozilla Maintenance Service (x32 Version: 26.0) Mozilla Thunderbird 24.2.0 (x86 de) (x32 Version: 24.2.0) MSVCRT Redists (Version: 1.0) MSVCRT Redists (x32 Version: 1.0) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) NTRIP (x32) NVIDIA Drivers (Version: 1.4) OpenOffice.org 3.4 (x32 Version: 3.4.9590) Paint.NET v3.5.10 (Version: 3.60.0) PaperPort Image Printer 64-bit (Version: 1.00.0000) PhotoScape (x32) PL-2303 USB-to-Serial (x32 Version: 1.4.17) Quick Media Converter Ask Toolbar Updater (HKCU Version: 1.2.0.20007) <==== ATTENTION QuickTime (x32 Version: 7.74.80.86) ScanSoft PaperPort 11 (x32 Version: 11.2.0000) Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (x32) Spybot - Search & Destroy (x32 Version: 2.0.12) Synaptics Pointing Device Driver (Version: 14.0.10.0) TomTom HOME (x32 Version: 2.9.6) TomTom HOME Visual Studio Merge Modules (x32) Überwachungstool für die Intel® Turbo-Boost-Technik (Version: 1.0.186.3) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update miniHomer 2.8 Version 2.8 (x32 Version: 2.8) Update miniHomer Version 2.6 (x32 Version: 2.6) Updater (x32 Version: 2.6.49) VIS (x32) VLC media player 2.1.0 (x32 Version: 2.1.0) VSO Image Resizer 4.0.2.5 (x32 Version: 4.0.2.5) Websteroids (x32 Version: 2.6.49) WIDCOMM Bluetooth Software (Version: 6.2.1.800) Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (Version: 07/30/2009 6.2.0.9405) Windows Driver Package - Broadcom Bluetooth (09/11/2009 6.2.0.9407) (Version: 09/11/2009 6.2.0.9407) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800) Windows Internet Explorer 10 (x32 Version: 10.0) Windows Live Family Safety (Version: 14.0.8118.427) Windows Live ID-Anmelde-Assistent (Version: 6.500.3165.0) WinRAR 5.00 (64-bit) (Version: 5.00.0) XMedia Recode 3.0.6.0 (x32 Version: 3.0.6.0) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ___AC C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {253AA94C-B81C-4ABE-957C-FAD1ACB9967E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {30A8F779-13BB-4F05-9A52-0787653C4CDA} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2009-12-14] (SAMSUNG Electronics) Task: {34B2FBD7-7971-44BB-8127-8664E93256E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2013-12-13] (AVAST Software) Task: {5A8D4D33-F9F7-49FA-90F6-3A0D6EDFCE6F} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe [2009-10-13] (Samsung Electronics Co., Ltd.) Task: {5BDCE4B0-9980-4211-828F-D2D7C61775AD} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2009-11-04] (Samsung Electronics Co., Ltd.) Task: {5C466351-1661-4AC2-A8CC-C5B327D34C8C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {5DEA853F-7A4D-43E8-9449-FE0E57B034BD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: {76044278-48D0-41B5-B1A8-93832FCCDF2C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23] (Google Inc.) Task: {7DF9C0E6-37F4-43E2-A928-39BDAA0648AB} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2009-10-16] (SAMSUNG Electronics co., LTD.) Task: {83558952-CA50-4A20-A13A-3EC5D8E21A8D} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-11-19] (Samsung Electronics. Co. Ltd.) Task: {9887809C-EA83-4BF8-8BB3-701D5D708A8F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23] (Google Inc.) Task: {9E2BC02C-B839-49C0-82AA-FE85FB334095} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {9F05B2AF-D111-4F97-88E5-0B2E112469F4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {B17A6072-0100-4950-A768-0A6F8177F7C2} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {B5AA7C9B-E68D-4359-AA63-B2ED2557B0FE} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe Task: {C135D8E8-FC1A-4546-B2C0-59F4F79A83E2} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC) Task: {CA283BEE-3EC0-466E-A81A-EB392CBC959D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {CEC26ED2-C2FA-4BA9-8C61-07CCAA3AE285} - System32\Tasks\APSchedulerC => C:\Program Files (x86)\AnyPC Client\APLanMgrC.exe [2009-11-20] (DoctorSoft) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-22 22:09 - 2013-12-22 17:58 - 02154496 _____ () C:\Program Files\Alwil Software\Avast5\defs\13122201\algo.dll 2010-02-09 07:08 - 2006-08-12 04:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll 2013-04-09 15:13 - 2012-11-13 13:06 - 00108960 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-04-09 15:13 - 2012-11-13 13:06 - 00416160 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-04-09 15:13 - 2012-11-13 13:06 - 00158624 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-04-09 15:13 - 2012-08-23 08:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-04-09 15:13 - 2012-11-13 13:06 - 00528288 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl 2013-05-01 11:48 - 2013-01-29 18:45 - 00112128 ____C () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll 2009-06-03 12:59 - 2009-06-03 12:59 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-06-03 12:59 - 2009-06-03 12:59 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2012-04-13 11:04 - 2012-04-13 11:04 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll 2012-04-13 11:00 - 2012-04-13 11:00 - 00170496 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll 2010-11-20 13:15 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll 2013-04-09 15:13 - 2012-11-13 13:06 - 00554400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl 2013-12-13 21:11 - 2013-12-13 21:11 - 19336120 _____ () C:\Program Files\Alwil Software\Avast5\libcef.dll 2002-07-27 23:53 - 2002-07-27 23:53 - 00040960 _____ () C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll 2002-08-20 20:01 - 2002-08-20 20:01 - 00134656 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll 2002-08-02 00:26 - 2002-08-02 00:26 - 00035328 _____ () C:\Program Files (x86)\Winamp\Plugins\in_wave.dll 2001-12-30 16:08 - 2001-12-30 16:08 - 00015360 _____ () C:\Program Files (x86)\Winamp\Plugins\out_disk.dll 2002-08-20 21:56 - 2002-08-20 21:56 - 00041984 _____ () C:\Program Files (x86)\Winamp\Plugins\out_ds.dll 2002-07-23 19:38 - 2002-07-23 19:38 - 00013824 _____ () C:\Program Files (x86)\Winamp\Plugins\out_wave.dll 2013-12-20 14:17 - 2013-12-20 14:18 - 03559024 ____C () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Broadcom BCM2070 Bluetooth 2.1+EDR USB Device Description: Broadcom BCM2070 Bluetooth 2.1+EDR USB Device Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Broadcom Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (12/22/2013 07:00:00 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "I:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" Error: (12/22/2013 10:05:28 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/22/2013 10:04:53 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/21/2013 03:46:29 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/21/2013 03:45:34 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/21/2013 09:21:01 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/21/2013 09:20:21 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (12/21/2013 09:20:20 AM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/21/2013 09:20:20 AM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (12/21/2013 09:20:20 AM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (12/22/2013 06:27:01 PM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (12/21/2013 04:05:02 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR5 gefunden. Error: (12/21/2013 03:58:22 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (12/21/2013 03:58:20 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (12/21/2013 03:58:19 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (12/21/2013 03:58:17 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (12/21/2013 03:58:15 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (12/21/2013 03:58:13 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (12/21/2013 03:58:12 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Error: (12/21/2013 03:58:10 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden. Microsoft Office Sessions: ========================= Error: (06/16/2012 08:29:52 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 176 seconds with 0 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 65% Total physical RAM: 3949.63 MB Available physical RAM: 1374.9 MB Total Pagefile: 7897.43 MB Available Pagefile: 5263.48 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (Lokal) (Fixed) (Total:79.62 GB) (Free:37.04 GB) NTFS Drive d: (Volume) (Fixed) (Total:331.98 GB) (Free:165.92 GB) NTFS Drive g: (Volume) (Fixed) (Total:39.06 GB) (Free:38.92 GB) NTFS Drive i: () (Removable) (Total:15.12 GB) (Free:2.97 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 2C06486A) Partition 1: (Not Active) - (Size=993 KB) - (Type=42) Partition 2: (Not Active) - (Size=15 GB) - (Type=27) Partition 3: (Active) - (Size=100 MB) - (Type=42) Partition 4: (Not Active) - (Size=80 GB) - (Type=42) ======================================================== Disk: 1 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ FRST.txt : FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-12-2013 01 Ran by max (administrator) on MAX-PC on 22-12-2013 22:36:40 Running from C:\Users\max\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe () C:\Windows\SysWOW64\Rezip.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Updater) C:\ProgramData\Updater\updater.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Cyberlink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe (WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe (WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe (Nullsoft) C:\Program Files (x86)\Winamp\winamp.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Users\max\Downloads\Defogger.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9644576 2009-12-15] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-10] (Synaptics Incorporated) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [481656 2013-11-20] (Updater) MountPoints2: {b31c6295-adf7-11e0-9982-b482fe37fbac} - G:\iStudio.exe HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink) HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePDRShortCut] - C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePPShortCut] - C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-07-21] (CyberLink Corp.) HKLM-x32\...\Run: [APLangApp] - C:\Program Files (x86)\AnyPC Client\APLangApp.exe [13312 2009-11-20] (DoctorSoft) HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl8] - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [83240 2008-03-20] (Cyberlink Corp.) HKLM-x32\...\Run: [PDVD8LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2007-12-14] () HKLM-x32\...\Run: [SSBkgdUpdate] - C:\Program Files (x86)\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [210472 2006-10-25] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PaperPort PTD] - C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.) HKLM-x32\...\Run: [PPort11reminder] - C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini [344 2011-07-23] () HKLM-x32\...\Run: [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1804240 2013-12-10] (APN) HKLM-x32\...\Run: [20131121] - C:\Program Files\Alwil Software\Avast5\Setup\emupdate\4c881f8e-9c6b-4fc0-a442-f3667a52b239.exe [180184 2013-11-23] (AVAST Software) HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [481656 2013-11-20] (Updater) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\Alwil Software\Avast5\AvastUI.exe [3568312 2013-12-13] (AVAST Software) Startup: C:\Users\max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk ShortcutTarget: OpenOffice.org 3.4.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yd.delta-search.com/?babsrc=HP_ss&mntrId=601EF67BCB2384C6&affID=119357&tt=040713_rdrctful&tsp=4937 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dsl-start.computerbild.de/?ie=10 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://dsl-start.computerbild.de/?ie=10 hxxp://mixidj.delta-search.com/?affID=121136&tt=190313_gr1&babsrc=HP_ss&mntrId=601EF67BCB2384C6 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://dsl-start.computerbild.de/?ie=10 hxxp://mixidj.delta-search.com/?affID=121136&tt=190313_gr1&babsrc=HP_ss&mntrId=601EF67BCB2384C6 URLSearchHook: HKCU - (No Name) - {37483b40-c254-4a72-bda4-22ee90182c1e} - No File URLSearchHook: HKCU - (No Name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No File SearchScopes: HKLM-x32 - DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 SearchScopes: HKLM-x32 - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.yd.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=601EF67BCB2384C6&affID=119357&tt=040713_rdrctful&tsp=4937 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=CCS&o=15773&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=HN&apn_dtid=YYYYYYYYDE&apn_uid=162CDC29-8D1D-48C7-9F3D-B25C4FB776F5&apn_sauid=0BDC4AAB-D63A-4BF4-AB04-C7384DF02DB4 SearchScopes: HKCU - {4301F923-6526-4B7B-9074-BFFC22CC5836} URL = hxxp://www.computerbild.de/suche/index.html?s_text={searchTerms} SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {965CD262-60AA-4711-BCE6-2C3AC22DDA48} URL = hxxp://de.search.yahoo.com/search?p={searchTerms} SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Websteroids - {44ed99e2-16a6-4b89-80d6-5b21cf42e78b} - C:\ProgramData\Websteroids\IE\common.dll (Creative Island Media, LLC) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {37483B40-C254-4A72-BDA4-22EE90182C1E} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730 FF NewTab: www.google.de FF DefaultSearchEngine: Ask Search FF SearchEngineOrder.1: Ask Search FF SelectedSearchEngine: Ask Search FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=1.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\searchplugins\ask-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: vis - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: Live Gold - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\livegold@dotcreation FF Extension: Websteroids - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\support@websteroidsapp.com FF Extension: DownloadHelper - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: Exif Viewer - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\exif_viewer@mozilla.doslash.org.xpi FF Extension: Ask Toolbar - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\toolbar_ORJ-V7@apn.ask.com.xpi FF Extension: NoScript - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: BetterPrivacy - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF Extension: DownThemAll! - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi FF Extension: Menu Editor - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF FF HKCU\...\Firefox\Extensions: [lwoofer@lyricswoofer.co] - C:\Program Files (x86)\LyricsWoofer\122.xpi FF HKCU\...\Firefox\Extensions: [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] - C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com/" CHR DefaultSearchKeyword: google.de CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR Extension: (Google Docs) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (VIS) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab CHR Extension: () - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\igjjkeeamkpihpncmmbgdkhdnjpcfmfb\2.6.49_0 CHR Extension: (Speed Test Analysis) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb\1.0.0.5_0 CHR Extension: (Google Wallet) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [jnikkfemnfogahcandhlchoengjbeaij] - C:\Program Files (x86)\LyricsWoofer\122.crx CHR HKLM-x32\...\Chrome\Extension: [kckgnnipheglejoddfhekdjpbdbinhmb] - C:\Users\max\AppData\Roaming\SpeedTestAnalysis\speedtestanalysis.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-10] (APN LLC.) R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2013-12-13] (AVAST Software) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.) R2 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [38984 2013-12-13] (AVAST Software) R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-12-13] (AVAST Software) R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-12-13] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-13] () R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1032416 2013-12-13] (AVAST Software) R1 aswSP; C:\windows\system32\drivers\aswSP.sys [409832 2013-12-13] (AVAST Software) R1 aswTdi; C:\windows\system32\drivers\aswTdi.sys [65264 2013-12-13] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-13] () S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [116264 2008-05-27] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-05-27] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [159784 2008-05-27] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [138792 2008-05-27] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-05-27] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [137768 2008-05-27] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [153128 2008-05-27] (MCCI Corporation) R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [12728 2009-09-29] () R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-22 22:36 - 2013-12-22 22:37 - 00022702 ____C C:\Users\max\Downloads\FRST.txt 2013-12-22 22:36 - 2013-12-22 22:36 - 00000000 ___DC C:\FRST 2013-12-22 22:35 - 2013-12-22 22:35 - 01928280 ____C (Farbar) C:\Users\max\Downloads\FRST64.exe 2013-12-22 22:34 - 2013-12-22 22:34 - 00000468 ____C C:\Users\max\Downloads\defogger_disable.log 2013-12-22 22:34 - 2013-12-22 22:34 - 00000000 ____C C:\Users\max\defogger_reenable 2013-12-22 22:33 - 2013-12-22 22:33 - 00050477 ____C C:\Users\max\Downloads\Defogger.exe 2013-12-22 16:16 - 2013-12-22 16:16 - 04379048 ____C (Piriform Ltd) C:\Users\max\Downloads\ccsetup407.exe 2013-12-22 10:05 - 2013-12-22 10:05 - 00000000 __RDC C:\Users\max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8 2013-12-20 14:17 - 2013-12-20 14:18 - 00000000 ___DC C:\Program Files (x86)\Mozilla Firefox 2013-12-18 21:22 - 2013-12-18 21:22 - 00000664 ____C C:\Users\max\Desktop\Filme_Michael_Caine.txt 2013-12-15 13:03 - 2013-12-15 13:03 - 00368343 ____C C:\Users\max\AppData\Local\recently-used.xbel 2013-12-14 08:53 - 2013-12-14 08:53 - 00000000 ___DC C:\Users\max\AppData\Roaming\AVAST Software 2013-12-13 21:10 - 2013-12-13 21:10 - 00000000 ___DC C:\ProgramData\AVAST Software 2013-12-11 20:11 - 2013-12-11 20:11 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2013-12-11 20:11 - 2013-12-11 20:11 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2013-12-11 20:11 - 2013-12-11 20:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2013-12-11 20:11 - 2013-12-11 20:11 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-12-11 20:09 - 2013-12-11 20:09 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-12-11 20:09 - 2013-12-11 20:09 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2013-12-11 20:09 - 2013-12-11 20:09 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-12-11 20:09 - 2013-12-11 20:09 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-12-11 20:09 - 2013-12-11 20:09 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-12-11 20:09 - 2013-12-11 20:09 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-12-11 18:51 - 2013-12-12 08:12 - 00000000 ___DC C:\Program Files (x86)\Mozilla Thunderbird 2013-12-11 08:21 - 2013-12-11 08:21 - 00000000 ___DC C:\Users\max\Documents\PC Speed Maximizer 2013-12-11 08:16 - 2013-12-11 08:16 - 00002768 ____C C:\windows\System32\Tasks\CCleanerSkipUAC 2013-12-11 08:16 - 2013-12-11 08:16 - 00000827 ____C C:\Users\Public\Desktop\CCleaner.lnk 2013-12-11 08:16 - 2013-12-11 08:16 - 00000000 ___DC C:\Program Files\CCleaner 2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Websteroids 2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Updater 2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\RHelpers 2013-12-11 08:13 - 2013-12-11 08:13 - 01080504 ____C (Conduit) C:\Users\max\Downloads\CCleaner_TSV426SC.exe 2013-12-11 08:04 - 2013-12-11 20:10 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-12-11 08:04 - 2013-12-11 20:10 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2013-12-11 08:04 - 2013-12-11 20:10 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll 2013-12-11 08:04 - 2013-12-11 20:10 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll 2013-12-11 08:04 - 2013-12-11 20:10 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll 2013-12-11 08:04 - 2013-12-11 20:09 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll 2013-12-11 08:04 - 2013-12-11 20:09 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll 2013-12-11 08:04 - 2013-12-11 20:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2013-12-11 08:04 - 2013-12-11 20:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-12-11 08:04 - 2013-12-11 20:08 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll 2013-12-11 08:04 - 2013-12-11 20:08 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe 2013-12-11 08:04 - 2013-12-11 20:08 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll 2013-12-11 08:04 - 2013-12-11 20:08 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe 2013-12-11 08:04 - 2013-12-11 20:08 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx 2013-12-11 08:04 - 2013-12-11 20:08 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe 2013-12-11 08:04 - 2013-12-11 20:08 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe 2013-12-11 08:04 - 2013-12-11 20:08 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx 2013-12-11 08:04 - 2013-10-04 03:16 - 00116736 ____C (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys 2013-12-11 08:04 - 2013-10-04 02:36 - 00230400 ____C (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys 2013-12-10 21:33 - 2013-12-10 21:33 - 09272200 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe ==================== One Month Modified Files and Folders ======= 2013-12-22 22:37 - 2013-12-22 22:36 - 00022702 ____C C:\Users\max\Downloads\FRST.txt 2013-12-22 22:36 - 2013-12-22 22:36 - 00000000 ___DC C:\FRST 2013-12-22 22:35 - 2013-12-22 22:35 - 01928280 ____C (Farbar) C:\Users\max\Downloads\FRST64.exe 2013-12-22 22:34 - 2013-12-22 22:34 - 00000468 ____C C:\Users\max\Downloads\defogger_disable.log 2013-12-22 22:34 - 2013-12-22 22:34 - 00000000 ____C C:\Users\max\defogger_reenable 2013-12-22 22:34 - 2010-04-06 09:07 - 00000000 ___DC C:\Users\max 2013-12-22 22:33 - 2013-12-22 22:33 - 00050477 ____C C:\Users\max\Downloads\Defogger.exe 2013-12-22 22:33 - 2012-04-15 06:51 - 00000884 ____C C:\windows\Tasks\Adobe Flash Player Updater.job 2013-12-22 22:16 - 2010-02-10 00:33 - 00654400 ____C C:\windows\system32\perfh007.dat 2013-12-22 22:16 - 2010-02-10 00:33 - 00130240 ____C C:\windows\system32\perfc007.dat 2013-12-22 22:16 - 2009-07-14 06:13 - 01498742 ____C C:\windows\system32\PerfStringBackup.INI 2013-12-22 21:57 - 2011-07-23 15:05 - 00001104 ____C C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-22 21:30 - 2010-02-09 06:58 - 01709460 ____C C:\windows\WindowsUpdate.log 2013-12-22 20:57 - 2011-07-23 15:05 - 00001100 ____C C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-22 18:21 - 2013-09-28 09:15 - 00000000 ___DC C:\Users\max\AppData\Roaming\vlc 2013-12-22 16:16 - 2013-12-22 16:16 - 04379048 ____C (Piriform Ltd) C:\Users\max\Downloads\ccsetup407.exe 2013-12-22 10:13 - 2009-07-14 05:45 - 00013936 ___HC C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-22 10:13 - 2009-07-14 05:45 - 00013936 ___HC C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-22 10:06 - 2012-07-10 13:58 - 00004184 ____C C:\windows\System32\Tasks\avast! Emergency Update 2013-12-22 10:05 - 2013-12-22 10:05 - 00000000 __RDC C:\Users\max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8 2013-12-22 10:03 - 2009-07-14 06:08 - 00000006 ___HC C:\windows\Tasks\SA.DAT 2013-12-21 09:19 - 2012-04-26 06:39 - 00000000 ___DC C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-20 14:18 - 2013-12-20 14:17 - 00000000 ___DC C:\Program Files (x86)\Mozilla Firefox 2013-12-19 22:08 - 2013-09-23 08:34 - 00000700 ____C C:\Users\max\Desktop\Film-Tips.txt 2013-12-18 21:22 - 2013-12-18 21:22 - 00000664 ____C C:\Users\max\Desktop\Filme_Michael_Caine.txt 2013-12-15 19:23 - 2013-08-01 21:03 - 00000000 ___DC C:\windows\system32\MRT 2013-12-15 19:22 - 2010-04-10 07:27 - 90708896 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-12-15 16:52 - 2013-06-19 12:32 - 00000000 ___DC C:\Users\max\.gimp-2.8 2013-12-15 13:03 - 2013-12-15 13:03 - 00368343 ____C C:\Users\max\AppData\Local\recently-used.xbel 2013-12-14 08:53 - 2013-12-14 08:53 - 00000000 ___DC C:\Users\max\AppData\Roaming\AVAST Software 2013-12-13 21:11 - 2013-03-19 16:22 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys 2013-12-13 21:11 - 2013-03-19 16:22 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys 2013-12-13 21:11 - 2012-02-26 13:20 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2013-12-13 21:11 - 2011-05-27 09:09 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2013-12-13 21:11 - 2011-01-21 12:45 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2013-12-13 21:11 - 2011-01-21 12:45 - 00043152 ____C (AVAST Software) C:\windows\avastSS.scr 2013-12-13 21:11 - 2010-04-22 05:41 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2013-12-13 21:11 - 2010-04-22 05:41 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2013-12-13 21:11 - 2010-04-22 05:41 - 00065264 _____ (AVAST Software) C:\windows\system32\Drivers\aswTdi.sys 2013-12-13 21:11 - 2010-04-22 05:41 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys 2013-12-13 21:11 - 2010-04-22 05:41 - 00001982 ____C C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-12-13 21:10 - 2013-12-13 21:10 - 00000000 ___DC C:\ProgramData\AVAST Software 2013-12-13 21:10 - 2010-04-22 05:41 - 00000000 ____C C:\windows\SysWOW64\config.nt 2013-12-12 08:12 - 2013-12-11 18:51 - 00000000 ___DC C:\Program Files (x86)\Mozilla Thunderbird 2013-12-12 08:01 - 2009-07-14 06:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2013-12-12 07:59 - 2009-07-14 05:45 - 00486968 ____C C:\windows\system32\FNTCACHE.DAT 2013-12-11 20:11 - 2013-12-11 20:11 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2013-12-11 20:11 - 2013-12-11 20:11 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2013-12-11 20:11 - 2013-12-11 20:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL 2013-12-11 20:11 - 2013-12-11 20:11 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll 2013-12-11 20:10 - 2013-12-11 08:04 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-12-11 20:10 - 2013-12-11 08:04 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2013-12-11 20:10 - 2013-12-11 08:04 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll 2013-12-11 20:10 - 2013-12-11 08:04 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll 2013-12-11 20:10 - 2013-12-11 08:04 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll 2013-12-11 20:10 - 2010-04-06 09:15 - 00000000 ___DC C:\ProgramData\Microsoft Help 2013-12-11 20:09 - 2013-12-11 20:09 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-12-11 20:09 - 2013-12-11 20:09 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-12-11 20:09 - 2013-12-11 20:09 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2013-12-11 20:09 - 2013-12-11 20:09 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-12-11 20:09 - 2013-12-11 20:09 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-12-11 20:09 - 2013-12-11 20:09 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-12-11 20:09 - 2013-12-11 20:09 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-12-11 20:09 - 2013-12-11 20:09 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-12-11 20:09 - 2013-12-11 08:04 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll 2013-12-11 20:09 - 2013-12-11 08:04 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll 2013-12-11 20:09 - 2013-12-11 08:04 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll 2013-12-11 20:09 - 2013-12-11 08:04 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll 2013-12-11 20:08 - 2013-12-11 08:04 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll 2013-12-11 20:08 - 2013-12-11 08:04 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe 2013-12-11 20:08 - 2013-12-11 08:04 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll 2013-12-11 20:08 - 2013-12-11 08:04 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe 2013-12-11 20:08 - 2013-12-11 08:04 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx 2013-12-11 20:08 - 2013-12-11 08:04 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe 2013-12-11 20:08 - 2013-12-11 08:04 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe 2013-12-11 20:08 - 2013-12-11 08:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx 2013-12-11 10:00 - 2013-10-25 05:43 - 00001716 ____C C:\Users\max\Desktop\Oberstdorf-Reisetips.txt 2013-12-11 08:21 - 2013-12-11 08:21 - 00000000 ___DC C:\Users\max\Documents\PC Speed Maximizer 2013-12-11 08:16 - 2013-12-11 08:16 - 00002768 ____C C:\windows\System32\Tasks\CCleanerSkipUAC 2013-12-11 08:16 - 2013-12-11 08:16 - 00000827 ____C C:\Users\Public\Desktop\CCleaner.lnk 2013-12-11 08:16 - 2013-12-11 08:16 - 00000000 ___DC C:\Program Files\CCleaner 2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Websteroids 2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Updater 2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\RHelpers 2013-12-11 08:13 - 2013-12-11 08:13 - 01080504 ____C (Conduit) C:\Users\max\Downloads\CCleaner_TSV426SC.exe 2013-12-10 21:33 - 2013-12-10 21:33 - 09272200 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe 2013-12-10 21:33 - 2012-04-15 06:51 - 00692616 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 21:33 - 2012-04-15 06:51 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 21:33 - 2011-10-07 17:41 - 00071048 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-09 20:02 - 2013-10-22 08:13 - 00002831 ____C C:\Users\max\Desktop\Fahrplan-Romantische_Schiene_EM_Noerdlingen.txt 2013-12-02 20:52 - 2011-07-23 15:05 - 00004100 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-02 20:52 - 2011-07-23 15:05 - 00003848 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-11-23 18:28 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache 2013-11-23 09:13 - 2013-03-16 19:51 - 00000000 ___DC C:\Users\max\Documents\Movie Studio Platinum 12.0 Projekte 2013-11-22 07:58 - 2010-04-14 07:51 - 00000000 ___DC C:\windows\Minidump 2013-11-22 07:58 - 2009-08-02 03:27 - 00000000 ___DC C:\windows\Panther ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-10 21:49 ==================== End Of Log ============================ --- --- --- --- --- --- |